SlipstreamJobsFresh Startup & VC-Backed Jobs

SOC Engineer - US

Inforcer - United States - Hybrid

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Inforcer is a cybersecurity solutions provider focused on helping Managed Service Providers (MSPs) manage Microsoft Security policies across multiple tenants. We are seeking a SOC Engineer to join our security operations team. You will serve as a frontline security operations professional, responsible for monitoring, investigating, and responding to security threats across our environment. This is a hands-on operational role with real ownership, ideal for someone who thrives in fast-paced settings and enjoys deep-diving into logs and complex network behaviors. Key Responsibilities: - Monitor SIEM, EDR/XDR, and security tooling for real-time alerts and suspicious activity - Triage, investigate, and document security incidents following established playbooks - Perform log analysis across network, endpoint, cloud, and identity systems to identify potential threats - Escalate incidents as needed and collaborate with Security Engineering, IT, and Incident Response teams - Support containment and remediation efforts, including isolating endpoints, collecting forensic artifacts, and validating indicators of compromise (IOCs) - Contribute to improving detection content by identifying gaps, false positives, and tuning opportunities - Participate in threat hunting exercises and proactive investigations into anomalous behavior - Maintain accurate incident records, timelines, and post-incident reporting - Assist with onboarding and operationalizing new security tools and processes - Stay current with emerging threats, attack techniques, and security best practices This role includes regular out-of-hours work as part of a 24/7 security operation, compensated as overtime. You will also help strengthen detection and response capabilities by improving playbooks and enhancing alert quality, directly supporting the organization's security posture and resilience. The company offers competitive compensation, pension contributions through Nest, flexible working hours, hybrid/remote options, regular team socials, continuous learning opportunities, professional training programs, and career advancement paths. Requirements: - Hands-on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, QRadar, LogRhythm) - Familiarity with EDR/XDR tools such as CrowdStrike, Microsoft Defender, SentinelOne, or Cortex - Ability to analyze logs from servers, endpoints, firewalls, IDS/IPS, and cloud environments - Understanding of common attack frameworks (MITRE ATT&CK) and threat actor behaviors - Basic knowledge of network security, TCP/IP, authentication flows, and identity logs - Experience responding to security incidents in a SOC or cyber operations environment - Strong analytical mindset with ability to spot patterns and anomalies - Clear written communication for incident documentation and escalation - Ability to stay calm and focused during high-pressure security events - Comfortable working in fast-paced, alert-driven operational environment - Collaborative, curious, and proactive about learning new threat vectors and tools - Exposure to scripting or automation (Python, PowerShell) is a plus - Relevant certifications helpful (Security+, CySA+, GSEC, GCIA, GCIH, CEH) but not required if experience is equivalent

Similar roles